Skip to content

Security: Backport uuidv8 vulnerabilty to v3 of msal-node too #8635

@destroyer22719

Description

@destroyer22719

Core Library

MSAL Node (@azure/msal-node)

Core Library Version

3

Wrapper Library

Not Applicable

Wrapper Library Version

N/A

Public or Confidential Client?

Confidential

Description

#8553

Can we backport the fix to v3 as well to those of us on the older versions in our projects? That would be appreciated as v3 is still LTS.

Error Message

No response

MSAL Logs

No response

Network Trace (Preferrably Fiddler)

  • Sent
  • Pending

MSAL Configuration

N/A

Relevant Code Snippets

N/A

Reproduction Steps

npm audit

Expected Behavior

the uuid CVE should be gone

Identity Provider

Entra ID (formerly Azure AD) / MSA

Browsers Affected (Select all that apply)

None (Server)

Regression

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    Needs: Attention 👋Awaiting response from the MSAL.js teambug-unconfirmedA reported bug that needs to be investigated and confirmedconfidential-clientIssues regarding ConfidentialClientApplicationsmsal-nodeRelated to msal-node packagequestionCustomer is asking for a clarification, use case or information.

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions